Authorization Flaw in Wired Impact Volunteer Management Plugin
CVE-2026-24997
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 February 2026
What is CVE-2026-24997?
The Wired Impact Volunteer Management plugin for WordPress is susceptible to a missing authorization vulnerability due to incorrectly configured access control security levels. This can allow unauthorized users to gain access to restricted functionalities, posing a significant security risk. Users are advised to update to the latest version to mitigate potential exploits.
Affected Version(s)
Wired Impact Volunteer Management 0 <= 2.8